EDBT 2026 Demo / reviewers in the wild / expert
Peter L. Reiher
dblp:r/PLReiher
· DBLP profile ↗
60ranked-venue papers
1as first author
6since 2021 · last 2024
0000-0002-5301-2246ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 19Security and privacy · 16 · 5 since 2021Systems, architecture and hardware · 10Software engineering, systems software and programming languages · 4Databases, data management, data science and information retrieval · 2Human-computer interaction and ubiquitous computing · 2
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | End-to-End Detection of Middlebox InterferenceabstractInternet middleboxes are an increasingly common network element. They can significantly alter the handling of traffic streams. Therefore, it is beneficial—and in some cases, crucial—to enable end-hosts to detect them. While transparent middleboxes interfere with the traffic, they do not change traffic content, giving the appearance that the data have merely been routed. This transparency makes end-to-end detection of such intermediaries particularly challenging. While existing ad hoc detection approaches apply only to a specific middlebox type, we present a general framework to detect a broad class of middleboxes. We use detecting transparent middleboxes as an example to illustrate our idea. We demonstrate our results by detecting three common middleboxes: network compression, traffic prioritization, and traffic shaping, using analysis, network simulations, and live Internet experiments with a real middlebox. Vahab Pournaghshband, Peter L. Reiher |
NOMS | 2 |
| 2024 | On Explainable and Adaptable Detection of Distributed Denial-of-Service TrafficabstractLaunched from numerous end-hosts throughout the Internet, a distributed denial-of-service (DDoS) attack can exhaust the network bandwidth or other resources of a victim, cripple its service, and make it unavailable to legitimate clients. Recently many learning-based approaches attempt to detect DDoS attacks, but their results are often hardly explainable to users and their models are seldom adaptable to new environments. In this paper, we propose a new learning-based DDoS detection approach. It detects DDoS attacks via an enhanced k-nearest neighbors (KNN) algorithm, which utilizes a k-dimensional (KD) tree to speed up the detection process, and classifies DDoS sources at a fine granularity according to each IP's risk level. Compared to previous DDoS detection approaches, this approach outputs explanatory information that enables network administrators to easily inspect detection results and make necessary interventions. Moreover, this approach is adaptable in that users do not need to retrain the detection model to have it fit with a new network environment. We evaluated this approach in both simulated environments and the real world, achieving more than 95.6% accuracy in detecting DDoS attacks at line speed. In addition, we carried out a human subject study on its explainability, demonstrating that the outputs can help people better understand the attack and make interventions precisely and promptly. Yebo Feng, Jun Li 0001, Devkishen Sisodia, Peter L. Reiher |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2023 | A Method for Summarizing and Classifying Evasive MalwareabstractEver since the earliest days of the Internet, malware has been a problem for computers. Since then, this problem’s severity has only increased, with important organizations like universities and hospitals suffering major security breaches due to malware. As detection techniques get more advanced, so do attackers’ evasion attempts. One such method involves introducing benign behavior to malware to produce a benign classification even while performing malicious actions. In this work, we propose a method of classifying malware that remains effective in the presence of such evasion attempts. Our contributions include generating a behavior summary, vectorizing it in a way that’s robust to modifications, and constraining features to reduce the effectiveness of these evasion techniques. Our results show that we can effectively and consistently classify such evasive malware with minimal accuracy loss in non-evasive data. Haikuo Yin, Brandon Lou, Peter L. Reiher |
RAID | 3 |
| 2023 | DDoS Mitigation Dilemma Exposed: A Two-Wave Attack with Collateral Damage of Millions
Lumin Shi, Jun Li 0001, Devkishen Sisodia, Mingwei Zhang 0004, Alberto Dainotti, Peter L. Reiher |
SecureComm (2) | 6 |
| 2023 | A Game Theoretical Analysis of Distributed Denial-of-Service Defense Incentive
Mingwei Zhang 0004, Jun Li 0001, Jiabin Wu, Peter L. Reiher |
SecureComm (2) | 4 |
| 2022 | On Capturing DDoS Traffic Footprints on the InternetabstractWhile distributed denial-of-service (DDoS) attacks are easy to launch and are becoming more damaging, the defense against DDoS attacks often suffers from the lack of relevant knowledge of the DDoS traffic, including the paths the DDoS traffic has used, the source addresses (spoofed or not) that appear along each path, and the amount of traffic per path or per source. Though IP traceback and path inference approaches could be considered, they are either expensive and hard to deploy or inaccurate. We propose PathFinder, a service that a DDoS defense system can use to obtain the footprints of the DDoS traffic to the victim. PathFinder employs an architecture that is easy to implement and deploy on today's Internet, a PFTrie data structure that introduces multiple design features to log traffic at line rate, and streaming and zooming mechanisms that facilitates the storage and transmission of DDoS footprints more efficiently. Our evaluation shows that PathFinder can significantly improve the efficacy of a DDoS defense system, its PFTrie data structure is fast and has a manageable overhead, and its streaming and zooming mechanisms significantly reduce the delay and overhead in transmitting DDoS footprints. Lumin Shi, Jun Li 0001, Mingwei Zhang 0004, Peter L. Reiher |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2019 | On Multi-Point, In-Network Filtering of Distributed Denial-of-Service Traffic
Mingwei Zhang 0004, Lumin Shi, Devkishen Sisodia, Jun Li 0001, Peter L. Reiher |
IM | 5 |
| 2019 | RIoT: A Rapid Exploit Delivery Mechanism against IoT Devices Using Vehicular BotnetsabstractVehicular ad hoc networks (VANETs) are designed to provide traffic safety by enabling vehicles to broadcast information-such as speed, location and heading-through inter-vehicular communications to proactively avoid collisions. However, one powerful threat against VANETs is vehicular botnets. In our earlier work, we demonstrated several powerful vehicular botnet attacks that can have damaging impacts on the security and privacy of VANETs. In this paper, we present RIoT-the first attack in the literature against Internet of Things (IoT) devices using vehicles-and demonstrate that vehicular botnets are threats not only to VANETs, but also to other important systems and networks. We show via simulation that RIoT can compromise up to 87 percent of the IoT devices in an area of interest within a short amount of time, by taking advantage of the mobility and collective communication range of vehicular bots. Mevlut Turker Garip, Peter L. Reiher, Mario Gerla |
VTC Fall | 2 |
| 2017 | RESECT: Self-Learning Traffic Filters for IP Spoofing DefenseabstractIP spoofing has been a persistent Internet security threat for decades. While research solutions exist that can help an edge network detect spoofed and reflected traffic, the sheer volume of such traffic requires handling further upstream. Jelena Mirkovic, Erik Kline, Peter L. Reiher |
ACSAC | 3 |
| 2017 | INTERLOC: An interference-aware RSSI-based localization and sybil attack detection mechanism for vehicular ad hoc networksabstractVehicular ad hoc networks (VANETs) are designed to provide traffic safety by exploiting the inter-vehicular communications. Vehicles build awareness of traffic in their surroundings using information broadcast by other vehicles, such as speed, location and heading, to proactively avoid collisions. The effectiveness of these VANET traffic safety applications is particularly dependent on the accuracy of the location information advertised by each vehicle. Therefore, traffic safety can be compromised when Sybil attackers maliciously advertise false locations or other inaccurate GPS readings are sent. The most effective way to detect a Sybil attack or correct the noise in the GPS readings is localizing vehicles based on the physical features of their transmission signals. The current localization techniques either are designed for networks where the nodes are immobile or suffer from inaccuracy in high-interference environments. In this paper, we present a RSSI-based localization technique that uses mobile nodes for localizing another mobile node and adjusts itself based on the heterogeneous interference levels in the environment. We show via simulation that our localization mechanism is more accurate than the other mechanisms and more resistant to environments with high interference and mobility. Mevlut Turker Garip, Paul Hyungmin Kim, Peter L. Reiher, Mario Gerla |
CCNC | 3 |
| 2016 | Datacomp: Locally Independent Adaptive Compression for Real-World SystemsabstractNon-lossy compression can save time and energy during communication if the cost to compress and send input is less than the cost of sending it uncompressed. Unfortunately, compression can also degrade performance, no single method is always beneficial, and outcomes depend on many factors. As a result, compression choices in real systems are coarsely grained and manually controlled, resulting in suboptimal or even poor performance. Adaptive Compression (AC) systems make compression choices dynamically to optimize utility. Existing AC systems are limited in ways that reduce their suitability for general-purpose computers. Datacomp is an AC system that operates locally and includes no significant hard-coded knowledge. Using real-world data, a broad range of environments and the Comptool "AC Oracle," we show that Datacomp's performance is equivalent or close to the ideal at bandwidths between 1-100Mbit/s, even when static strategies are suboptimal or more costly than no compression. While Datacomp struggles to perform well at 1Gbit/s, understanding why illustrates important challenges for AC systems and suggests solutions. Peter Peterson, Peter L. Reiher |
ICDCS | 2 |
| 2016 | Ghost: Concealing vehicular botnet communication in the VANET control channelabstractVehicular ad hoc networks (VANETs) are expected to play a big role in our lives in the near future; they will both improve traffic safety and revolutionize the driving experience. Their expected deployment in autonomous cars will induce attackers to design new methods to target these systems, and to organize the vehicles they compromise into vehicular botnets. Vehicular botnets enable new attacks that reveal previously unknown security flaws in VANETs. Effectively defending against such botnets requires investigation of their characteristics and of the attacks that these cooperating malicious vehicles can perform on VANETs. One important characteristic of a botnet is the way its members communicate to coordinate their attacks, with an emphasis on stealth. In this paper, we investigate alternatives for vehicular botnets to communicate to perform attacks. We design and demonstrate a VANET-based botnet communication protocol that hides itself in the ongoing network traffic over the control channel. We show via simulation that it is infeasible to detect such botnet communications due to the vulnerabilities existing in the VANET standards, and discuss possible countermeasures. Mevlut Turker Garip, Peter L. Reiher, Mario Gerla |
IWCMC | 2 |
| 2015 | Scalable reactive vehicle-to-vehicle congestion avoidance mechanismabstractThe increasing popularity and acceptance of VANETs will make the deployment of autonomous vehicles easier and faster since the VANET will reduce dependence on expensive sensors. Many useful applications will be possible with the usage of VANETs, which will improve the safety and quality of trips for the owners of these vehicles. One of these applications is the avoidance of traffic congestion by smart dynamic rerouting. For scalability, current cloud-based solutions, like Google Maps traffic, update congestion levels after a time interval rather than providing real-time measurements. In this paper, we introduce a vehicle-to-vehicle congestion avoidance mechanism, which detects real-time congestion levels and reroutes vehicles accordingly to minimize their trip times. Our system is highly distributed and is, therefore, not subjected to the limitations of centralized congestion avoidance mechanisms. We show via simulation that our system can significantly decrease the trip times of vehicles as well as the average car density on the map. Our proposed system, with its checkpoint and offline path generation approaches, is more responsive to local congestion level changes and computationally less complex for least congested route calculations than state-of-the-art congestion avoidance mechanisms. Mevlut Turker Garip, Mehmet Emre Gursoy, Peter L. Reiher, Mario Gerla |
CCNC | 3 |
| 2015 | Cashtags: Protecting the Input and Display of Sensitive Data
Michael Mitchell, An-I Wang, Peter L. Reiher |
USENIX Security Symposium | 3 |
| 2014 | End-to-end detection of compression of traffic flows by intermediariesabstractRouters or nodes on the Internet sometimes apply link-layer or IP-level compression on traffic flows with no knowledge of the end-hosts. If the end-host applications are aware of the compression already provided by an intermediary, they can save time and resources by not applying compression themselves. The benefits from these savings are even greater in mobile applications. We present a probing technique to detect the compression of traffic flows by intermediaries. Our technique is non-intrusive and robust to cross traffic. It is entirely end-to-end, requiring neither changes to nor information from intermediate nodes. We present two different but similar approaches based on how cooperative the end-hosts are. Our proposed technique only uses packet inter-arrival times for detection. It does not require synchronized clocks at the sender and receiver. Simulations and Internet experiments were used to evaluate our approach. Our findings demonstrate an accurate detection of compression applied to traffic flows by intermediaries. Vahab Pournaghshband, Alexander Afanasyev, Peter L. Reiher |
NOMS | 3 |
| 2014 | Drawbridge: software-defined DDoS-resistant traffic engineeringabstractEnd hosts in today's Internet have the best knowledge of the type of traffic they should receive, but they play no active role in traffic engineering. Traffic engineering is conducted by ISPs, which unfortunately are blind to specific user needs. End hosts are therefore subject to unwanted traffic, particularly from Distributed Denial of Service (DDoS) attacks. This research proposes a new system called DrawBridge to address this traffic engineering dilemma. By realizing the potential of software-defined networking (SDN), in this research we investigate a solution that enables end hosts to use their knowledge of desired traffic to improve traffic engineering during DDoS attacks. Jun Li 0001, Skyler Berg, Mingwei Zhang 0004, Peter L. Reiher, Tao Wei 0002 |
SIGCOMM | 4 |
| 2013 | Improving the security of Android inter-component communication
Adam Cozzette, Kathryn Lingel, Steve Matsumoto, Oliver Ortlieb, Jandria Alexander, Joseph Betser, Luke Florer, Geoffrey H. Kuenning, John Nilles, Peter L. Reiher |
IM | 10 |
| 2012 | Data Tethers: Preventing information leakage by enforcing environmental data access policiesabstractProtecting data from accidental loss or theft is crucial in today's world of mobile computing. Data Tethers provides flexible environmental policies, which can be attached to data, specifying security requirements that must be met before accessing that data. Data Tethers uses fine-grain data flow tracking to maintain these policies on derivative data. This is implemented by dynamic recompilation of legacy applications without the need to recompile from source. We demonstrate the system's feasibility with microbenchmarks that show individual component performance and benchmarks of real user applications like word processors and spreadsheets. Charles Fleming, Peter Peterson, Erik Kline, Peter L. Reiher |
ICC | 4 |
| 2012 | Controlling applications by managing network characteristicsabstractEdge network operators have limited tools to control activities on their networks. This paper examines network dissuasion, a new approach to edge network control, based on controlling the fundamental parameters of the network, such as loss rate, delay, and jitter, with the intention of making particular uses of a network intolerable, while providing acceptable services for approved network uses. We investigate using this technique to prevent use of Voice Over IP (VoIP), while allowing other services. We designed network controls to achieve this goal and performed experiments using both measurements and subjective testing with human beings. We report on the degree of success and discuss the general promise of network dissuasion. Vahab Pournaghshband, Leonard Kleinrock, Peter L. Reiher, Alexander Afanasyev |
ICC | 3 |
| 2012 | Scaling Down Off-the-Shelf Data Compression: Backwards-Compatible Fine-Grain MixingabstractPu and Singaravelu presented Fine-Grain Mixing, an adaptive compression system which aimed to maximize CPU and network utilization simultaneously by splitting a network stream into a mixture of compressed and uncompressed blocks. Blocks were compressed opportunistically in a send buffer, they compressed as many blocks as they could without becoming a bottleneck. They successfully utilized all available CPU and network bandwidth even on high speed connections. In addition, they noted much greater throughput than previous adaptive compression systems. Here, we take a different view of FG-Mixing than was taken by Pu and Singaravelu and give another explanation for its high performance: that fine-grain mixing of compressed and uncompressed blocks enables off-the-shelf compressors to scale down their degree of compression linearly with decreasing CPU usage. Exploring the scaling behavior in-depth allows us to make a variety of improvements to fine-grain mixed compression: better compression ratios for a given level of CPU consumption, a wider range of data reduction and CPU cost options, and parallelized compression to take advantage of multi-core CPUs. We make full compatibility with the ubiquitous deflate decompress or (as used in many network protocols directly, or as the back-end of the gzip and Zip formats) a primary goal, rather than using a special, incompatible protocol as in the original implementation of FG-Mixing. Moreover, we show that the benefits of fine-grain mixing are retained by our compatible version. Michael Gray, Peter Peterson, Peter L. Reiher |
ICDCS | 3 |
| 2011 | Shield: DoS filtering using traffic deflectingabstractDenial-of-service (DoS) attacks continue to be a major problem on the Internet. While many defense mechanisms have been created, they all have significant deployment issues. This paper introduces a novel method that overcomes these issues, allowing a small number of deployed DoS defenses to act as secure on-demand shields for any node on the Internet. The proposed method is based on rerouting any packet addressed to a protected autonomous system (AS) through an intermediate filtering node-a shield. In this way, all potentially harmful traffic could be discarded before reaching the destination. The mechanisms for packet rerouting use existing routing techniques and do not require any kind of modification to the deployed protocols or routers. To make the proposed system feasible, from both deployment and usage points of view, traffic rerouting and outsourced filtering could be provided as an insurance-style on-demand service. Erik Kline, Alexander Afanasyev, Peter L. Reiher |
ICNP | 3 |
| 2011 | A Dynamic Recursive Unified Internet Design (DRUID)
Joseph D. Touch, Ilya Baldin, Rudra Dutta, Gregory G. Finn, Bryan Ford, Scott Jordan 0001, Daniel Massey, Abraham Matta, Christos Papadopoulos, Peter L. Reiher, George N. Rouskas |
Comput. Networks | 10 |
| 2009 | RAD: Reflector Attack Defense Using Message Authentication CodesabstractReflector attacks are a variant of denial-of-service attacks that use unwitting, legitimate servers to flood a target. The attacker spoofs the target's address in legitimate service requests, such as TCP SYN packets. The servers, called "reflectors,'' reply to these requests, flooding the target. RAD is a novel defense against reflector attacks. It has two variants -- locally-deployed (L-RAD) and core-deployed (C-RAD). Local RAD uses message authentication codes (MACs) to mark outgoing requests at their source, so the target of a reflector attack can differentiate between replies to legitimate and spoofed requests. MACs can be validated either at the target machine or on a gateway router at the target's network. Core RAD, which is deployed at the AS level, handles larger attacks that overwhelm L-RAD. The source AS marks each packet it sends with a hash message authentication code (HMAC) and core ASes filter packets that carry incorrect HMACs. C-RAD prevents reflector attacks by filtering spoofed requests, rather than filtering reflected replies. We tested both variants using the DETER testbed by replaying backbone traces from the MAWI project archive in a congestion-responsive manner. Our tests show that local RAD is better than the no-defense case, but gets overwhelmed when the attack exceeds the target's network capacity. Core-deployed RAD successfully handles attacks of all rates. Erik Kline, Matt Beaumont-Gay, Jelena Mirkovic, Peter L. Reiher |
ACSAC | 4 |
| 2009 | Securing data through avoidance routingabstractAs threats on the Internet become increasingly sophisticated, we now recognize the value in controlling the routing of data in a manner that ensures security. However, few technical means for achieving this goal exist. In this paper we propose and design a system that allows users to specify regions of the Internet they wish their data to avoid. Using our system, data will either arrive at the destination along a path that avoids the specified regions, or no avoiding path exists. Beyond the design, we discuss the deployment, performance and security issues of this system, along with alternative approaches that could be used. Categories and Subject Descriptors C.2.0 [General]: Security and protection; C.2.2 [Network Erik Kline, Peter L. Reiher |
NSPW | 2 |
| 2009 | Distributed Policy Resolution Through Negotiation in Ubiquitous Computing EnvironmentsabstractEnsuring spontaneous ad hoc interoperation in decentralized ubiquitous computing environments is challenging, because of heterogeneous resources and divergent policies. Centralized cross-domain service access agreements can be made with a priori knowledge of the interacting entities' policies, but privacy concerns make this approach impractical. Environments should not be too rigid nor too open in their interactions, and should support varying contexts and scenarios. We describe the modeling, design, and implementation of a general purpose negotiation protocol for cross-domain service access agreements between entities that do not share trust agreements or application level protocols. This protocol resolves the constraints and needs of the participants, described in the form of declarative logical policies, in a fully distributed manner, avoiding the need for a third party. We describe how we tested the system and show how negotiation performance was evaluated against an optimal case computed by a centralized oracle. Venkatraman Ramakrishna, Peter L. Reiher, Leonard Kleinrock |
PerCom | 2 |
| 2009 | Accurately Measuring Denial of Service in Simulation and Testbed ExperimentsabstractResearchers in the denial-of-service (DoS) field lack accurate, quantitative, and versatile metrics to measure service denial in simulation and testbed experiments. Without such metrics, it is impossible to measure severity of various attacks, quantify success of proposed defenses, and compare their performance. Existing DoS metrics equate service denial with slow communication, low throughput, high resource utilization, and high loss rate. These metrics are not versatile because they fail to monitor all traffic parameters that signal service degradation. They are not quantitative because they fail to specify exact ranges of parameter values that correspond to good or poor service quality. Finally, they are not accurate since they were not proven to correspond to human perception of service denial. We propose several DoS impact metrics that measure the quality of service experienced by users during an attack. Our metrics are quantitative: they map QoS requirements for several applications into measurable traffic parameters with acceptable, scientifically determined thresholds. They are versatile: they apply to a wide range of attack scenarios, which we demonstrate via testbed experiments and simulations. We also prove metrics' accuracy through testing with human users. Jelena Mirkovic, Alefiya Hussain, Sonia Fahmy, Peter L. Reiher, Roshan K. Thomas |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2008 | The Smart Party: A Personalized Location-Aware Multimedia ExperienceabstractThe Smart Party is a new ubiquitous computing application for the home environment. This application gathers musical preferences for guests located in different rooms of a user's house. Based on their preferences and available media, the application chooses a music play list for each room, adjusting to changing membership as guests move through the party. We describe the application, its architecture, and our implementation, including key performance characteristics. Kevin Eustice, Venkatraman Ramakrishna, Nam T. Nguyen, Peter L. Reiher |
CCNC | 4 |
| 2008 | Johnny Appleseed: wardriving to reduce interference in chaotic wireless deploymentsabstractMany areas have dense deployments of 802.11 wireless access points, often with little or no planning of the best choices of channel assignments. As a result, there is often very high interference due to poor channel assignments. One contributing factor is that many access points are deployed with the absolute minimum of configuration effort, which means they are assigned to the channel the manufacturer has chosen, as a default. In many cases, such minimal effort deployments also mean that the access point uses the manufacturer-default password. Inspired by Johnny Appleseed, a 19th century American altruist who wandered the wilderness planting apple trees for the use of others, we investigate a method by which an altruistic wardriver moving through a dense wireless deployment could take advantage of such minimally configured access points. Where possible, he could use the default passwords to log into the system and change the channel assignment to better suite the surrounding environment, reducing interference for all. We examine this solution in simulation using real data gathered by wardrivers in several locations. We demonstrate that even with some conservative assumptions on the number of access points our Johnny Appleseed could alter, simple single-pass algorithms can result in a 10% reduction of total interference in a dense wireless deployment. We discuss the legal and ethical implications of the approach. Tim Dasilva, Kevin Eustice, Peter L. Reiher |
MSWiM | 3 |
| 2008 | Improving User Satisfaction in a Ubiquitous Computing ApplicationabstractThe Smart Party is a ubiquitous computing application based on the Panoply middleware. The Smart Party allows attendees at a party to transparently participate in the selection of music played at the party. The methods used to select music, based on the preferences of the party goers, has a substantial impact on how satisfied these party goers will be. This paper examines different algorithms for selecting music in a Smart Party, and discusses lessons from the research that are applicable to other socially-based ubicomp applications. Kevin Eustice, A. M. Jourabchi, J. Stoops, Peter L. Reiher |
WiMob | 4 |
| 2008 | Message from the SAUCE Workshop Organizing Technical Co-chairsabstractPresents the introductory welcome message from the conference proceedings. Peter L. Reiher, John Zimmerman, Kevin Eustice |
WiMob | 1 |
| 2008 | Learning the valid incoming direction of IP packets
Jun Li 0001, Jelena Mirkovic, Toby Ehrenkranz, Mengqiu Wang, Peter L. Reiher, Lixia Zhang 0001 |
Comput. Networks | 5 |
| 2008 | Testing a Collaborative DDoS Defense In a Red Team/Blue Team ExerciseabstractTesting security systems is challenging because a system's authors have to play the double role of attackers and defenders. Red team/blue team exercises are an invaluable mechanism for security testing. They partition researchers into two competing teams of attackers and defenders, enabling them to create challenging and realistic test scenarios. While such exercises provide valuable insight into vulnerabilities of security systems, they are very expensive and thus rarely performed. In this paper we describe a red team/blue team exercise, sponsored by DARPA's FTN program, and performed October 2002 --- May 2003. The goal of the exercise was to evaluate a collaborative DDoS defense, comprised of a distributed system, COSSACK, and a stand-alone defense, D-WARD. The role of the blue team was played by developers of the tested systems from USC/ISI and UCLA, the red team included researchers from Sandia National Laboratory, and all the coordination, experiment execution, result collection and analysis was performed by the white team from BBN Technologies. This exercise was of immense value to all involved --- it uncovered significant vulnerabilities in tested systems, pointed out desirable characteristics in DDoS defense systems (e.g., avoiding reliance on timing mechanisms), and taught us many lessons about testing of DDoS defenses. Jelena Mirkovic, Peter L. Reiher, Christos Papadopoulos, Alefiya Hussain, Marla Shepard, Michael Berg, Robert Jung |
IEEE Trans. Computers | 2 |
| 2007 | PARAID: A Gear-Shifting Power-Aware RAID
Charles Weddle, Mathew Oldham, An-I Wang, Peter L. Reiher, Geoffrey H. Kuenning |
FAST | 5 |
| 2007 | Information protection via environmental data tethersabstractFaced with an increasing number of incidents involving leaks of confidential data, it is clear that new data protection strategies are needed. We propose Data Tethers, a new paradigm which uses policies based on environmental factors to determine when sensitive data may be stored on a machine and when it must be encrypted or removed from the machine entirely. We discuss a number of example scenarios where existing data protection systems provide insufficient protection and Data Tethers would prevent data exposure. We also discuss a proposed implementation of Data Tethers, including a number of different environmental inputs. Matt Beaumont-Gay, Kevin Eustice, Peter L. Reiher |
NSPW | 3 |
| 2007 | When is service really denied?: a user-centric dos metricabstractDenial-of-service (DoS) research community lacks accurate metrics to evaluate an attack's impact on network services, its severity and the effectiveness of a potential defense. We propose several DoS impact metrics that measure the quality of service experienced by end users during an attack, and compare these measurements to application-specific thresholds. Our metrics are ideal for testbed experimentation, since necessary traffic parameters are extracted from packet traces gathered during an experiment. Jelena Mirkovic, Alefiya Hussain, Brett Wilson, Sonia Fahmy, Wei-Min Yao, Peter L. Reiher, Stephen Schwab, Roshan K. Thomas |
SIGMETRICS | 6 |
| 2007 | PARAID: A gear-shifting power-aware RAIDabstractReducing power consumption for server-class computers is important, since increased energy usage causes more heat dissipation, greater cooling requirements, reduced computational density, and higher operating costs. For a typical data center, storage accounts for 27% of energy consumption. Conventional server-class RAIDs cannot easily reduce power because loads are balanced to use all disks, even for light loads. We have built the power-aware RAID (PARAID), which reduces energy use of commodity server-class disks without specialized hardware. PARAID uses a skewed striping pattern to adapt to the system load by varying the number of powered disks. By spinning disks down during light loads, PARAID can reduce power consumption, while still meeting performance demands, by matching the number of powered disks to the system load. Reliability is achieved by limiting disk power cycles and using different RAID encoding schemes. Based on our five-disk prototype, PARAID uses up to 34% less power than conventional RAIDs while achieving similar performance and reliability. Charles Weddle, Mathew Oldham, An-I Wang, Peter L. Reiher, Geoffrey H. Kuenning |
ACM Trans. Storage | 5 |
| 2006 | A Framework for a Collaborative DDoS DefenseabstractIncreasing use of the Internet for critical services makes flooding distributed denial-of-service (DDoS) a top security threat. A distributed nature of DDoS suggests that a distributed mechanism is necessary for a successful defense. Three main DDoS defense functionalities -- attack detection, rate limiting and traffic differentiation -- are most effective when performed at the victim-end, core and sourceend respectively. Many existing systems are successful in one aspect of defense, but none offers a comprehensive solution and none has seen a wide deployment. We propose to harvest the strengths of existing defenses by organizing them into a collaborative overlay, called DefCOM, and augmenting them with communication and collaboration functionalities. Nodes collaborate during the attack to spread alerts and protect legitimate traffic, while rate limiting the attack. DefCOM can accommodate existing defenses, provide synergistic response to attacks and naturally lead to an Internet-wide response to DDoS threat. George C. Oikonomou, Jelena Mirkovic, Peter L. Reiher, Max Robinson |
ACSAC | 3 |
| 2006 | The Conquest file system: Better performance through a disk/persistent-RAM hybrid designabstractModern file systems assume the use of disk, a system-wide performance bottleneck for over a decade. Current disk caching and RAM file systems either impose high overhead to access memory content or fail to provide mechanisms to achieve data persistence across reboots.The Conquest file system is based on the observation that memory is becoming inexpensive, which enables all file system services to be delivered from memory, except for providing large storage capacity. Unlike caching, Conquest uses memory with battery backup as persistent storage, and provides specialized and separate data paths to memory and disk. Therefore, the memory data path contains no disk-related complexity. The disk data path consists of optimizations only for the specialized disk usage pattern.Compared to a memory-based file system, Conquest incurs little performance overhead. Compared to several disk-based file systems, Conquest achieves 1.3x to 19x faster memory performance, and 1.4x to 2.0x faster performance when exercising both memory and disk. Conquest realizes most of the benefits of persistent RAM at a fraction of the cost of a RAM-only solution. It also demonstrates that disk-related optimizations impose high overheads for accessing memory content in a memory-rich environment. An-I Wang, Geoffrey H. Kuenning, Peter L. Reiher, Gerald J. Popek |
ACM Trans. Storage | 3 |
| 2005 | Introducing permuted states for analyzing conflict rates in optimistic replicationabstractNo abstract available. An-I Wang, Peter L. Reiher, Geoffrey H. Kuenning |
SIGMETRICS | 2 |
| 2005 | D-WARD: A Source-End Defense against Flooding Denial-of-Service AttacksabstractDefenses against flooding distributed denial-of-service (DDoS) commonly respond to the attack by dropping the excess traffic, thus reducing the overload at the victim. The major challenge is the differentiation of the legitimate from the attack traffic, so that the dropping policies can be selectively applied. We propose D-WARD, a source-end DDoS defense system that achieves autonomous attack detection and surgically accurate response, thanks to its novel traffic profiling techniques, the adaptive response and the source-end deployment. Moderate traffic volumes seen near the sources, even during the attacks, enable extensive statistics gathering and profiling, facilitating high response selectiveness. D-WARD inflicts an extremely low collateral damage to the legitimate traffic, while quickly detecting and severely rate-limiting outgoing attacks. D-WARD has been extensively evaluated in a controlled testbed environment and in real network operation. Results of selected tests are presented in the paper. Jelena Mirkovic, Peter L. Reiher |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2004 | Resilient self-organizing overlay networks for security update deliveryabstractRapid and widespread dissemination of security updates throughout the Internet will be invaluable for many purposes, including sending early-warning signals, updating certificate revocation lists, distributing new virus signatures, etc. Notifying a large number of machines securely, quickly, and reliably is challenging. Such a system must outpace the propagation of threats, handle complexities in a large-scale environment, deal with interruption attacks on dissemination, and also secure itself. Revere addresses these problems by building a large-scale, self-organizing, and resilient overlay network on top of the Internet. We discuss how to secure the dissemination procedure and the overlay network, considering possible attacks and countermeasures. We present experimental measurements of a prototype implementation of Revere gathered using a large-scale-oriented approach. These measurements suggest that Revere can deliver security updates at the required scale, speed and resiliency for a reasonable cost. Jun Li 0001, Peter L. Reiher, Gerald J. Popek |
IEEE J. Sel. Areas Commun. | 2 |
| 2004 | Roam: A Scalable Replication System for Mobility
David Ratner, Peter L. Reiher, Gerald J. Popek |
Mob. Networks Appl. | 2 |
| 2003 | Source-End DDoS DefenseabstractA successful source-end DDoS (distributed denial-of-service) defense enables early suppression of the attack and minimizes collateral damage. However, such an approach faces many challenges: (a) distributing the attack hinders detection; (b) defense systems must guarantee good service to legitimate traffic during the attack; and (c) deployment costs and false alarm levels must be sufficiently small and effectiveness must be high to provide deployment incentive. We discuss each of the challenges and describe one successful design of a source-end DDoS defense system-the D-WARD system. D-WARD was implemented in a Linux router. We include experimental results to illustrate D-WARD's performance. Jelena Mirkovic, Gregory Prier, Peter L. Reiher |
NCA | 3 |
| 2003 | Securing nomads: the case for quarantine, examination, and decontaminationabstractThe rapid growth and increasing pervasiveness of wireless networks raises serious security concerns. Client devices will migrate between numerous diverse wireless environments, bringing with them software vulnerabilities and possibly malicious code. Techniques are needed to protect wireless client devices and the next generation wireless infrastructure. We propose QED, a new security model for wireless networks that enables wireless environments to quarantine devices and then analyze and potentially update or "decontaminate" client nodes. The QED paradigm is presented here, as well as the design of a practical prototype. Kevin Eustice, Leonard Kleinrock, Shane Markstrum, Gerald J. Popek, Venkatraman Ramakrishna, Peter L. Reiher |
NSPW | 6 |
| 2003 | Alliance formation for DDoS defenseabstractCurrently, there is no effective defense against large-scale distributed denial-of-service (DDoS) attacks. While numerous DDoS defense systems exist that offer excellent protection from specific attack types and scenarios, they can frequently be defeated by an attacker aware of their weaknesses. A necessary requirement for successful DDoS defense is wide deployment, but none of these systems can guarantee wide deployment simply because deployment depends more on market and social aspects than on the technical performance of the system.To successfully handle the DDoS threat we must abandon the current paradigm---the design of defense systems that operate in isolation---and shift toward a new paradigm, a distributed framework of heterogeneous systems that cooperate to achieve an effective defense. Heterogeneity is dictated by two major factors. First, the necessary requirements for a successful defense are detection, response and traffic differentiation. These requirements must be met at disjoint points in the Internet and require a disjoint set of functionalities from the defense systems. Second, heterogeneity is dictated by the current state of the DDoS defense field in which numerous systems exist that can offer similar performance and compete for market share. In this paper we show how the paradigm shift can be accomplished quickly and painlessly through the design of DefCOM, a distributed framework that enables the exchange of information and services between existing defense nodes. Jelena Mirkovic, Max Robinson, Peter L. Reiher |
NSPW | 3 |
| 2002 | Attacking DDoS at the SourceabstractDistributed denial-of-service (DDoS) attacks present an Internet-wide threat. We propose D-WARD, a DDoS defense system deployed at source-end networks that autonomously detects and stops attacks originating from these networks. Attacks are detected by the constant monitoring of two-way traffic flows between the network and the rest of the Internet and periodic comparison with normal flow models. Mismatching flows are rate-limited in proportion to their aggressiveness. D-WARD offers good service to legitimate traffic even during an attack, while effectively reducing DDoS traffic to a negligible level. A prototype of the system has been built in a Linux router. We show its effectiveness in various attack scenarios, discuss motivations for deployment, and describe associated costs. Jelena Mirkovic, Gregory Prier, Peter L. Reiher |
ICNP | 3 |
| 2002 | SAVE: Source Address Validity Enforcement ProtocolabstractForcing all IP packets to carry correct source addresses can greatly help network security, attack tracing, and network problem debugging. However, due to asymmetries in today's Internet routing, routers do not have readily available information to verify the correctness of the source address for each incoming packet. In this paper we describe a new protocol, named SAVE, that can provide routers with the information needed for source address validation. SAVE messages propagate valid source address information from the source location to all destinations, allowing each router along the way to build an incoming table that associates each incoming interface of the router with a set of valid source address blocks. This paper presents the protocol design and evaluates its correctness and performance by simulation experiments. The paper also discusses the issues of protocol security, the effectiveness of partial SAVE deployment, and the handling of unconventional forms of network routing, such as mobile IP and tunneling. Jun Li 0001, Jelena Mirkovic, Mengqiu Wang, Peter L. Reiher, Lixia Zhang 0001 |
INFOCOM | 4 |
| 2002 | Simplifying automated hoarding methodsabstractA number of mobile computing systems have used the technique of hoarding, which allows a mobile device to store a chosen subset of known files, to give disconnected users the illusion of a complete filesystem in the presence of limited storage. We undertook an extensive and detailed simulation study of the parameters of a well-known hoarding system, seer, in an attempt to discover the parameters that would produce the best performance. To our surprise, we discovered that the best parameter combinations were those that completely disabled seer's complex clustering methods, reverting the system instead to a modified form of LRU hoarding. We discuss the experiments and our results, and propose designs for future systems and directions for future research. Geoffrey H. Kuenning, Wilkie Ma, Peter L. Reiher, Gerald J. Popek |
MSWiM | 3 |
| 2002 | Conquest: Better Performance Through a Disk/Persistent-RAM Hybrid File System
An-I Wang, Peter L. Reiher, Gerald J. Popek, Geoffrey H. Kuenning |
USENIX ATC, General Track | 2 |
| 2002 | Securing distributed adaptation
Jun Li 0001, Mark Yarvis, Peter L. Reiher |
Comput. Networks | 3 |
| 2001 | The Conquest File System's Life after DisksabstractSummary form only given. The Conquest file system is designed to provide a transition from disk- to persistent-RAM-based storage. Initially, we assume 2 to 4 Gbytes of persistent RAM and the popular single-user desktop environment. Unlike other memory file systems, Conquest can incrementally assume more responsibility for in-core storage as memory prices decline. The Conquest approach realizes most of the benefits of persistent-RAM-based file systems before persistent RAM becomes cheaply abundant. Conquest also benefits from the removal of disks as the primary storage by identifying disk-related complexities and isolating them from the critical path where possible. The Conquest prototype is operational under Linux 2.4.2. It is POSIX compliant and supports both in-core and on-disk storage. An-I Wang, Peter L. Reiher, Gerald J. Popek, Geoffrey H. Kuenning |
HotOS | 2 |
| 2001 | The Bengal Database Replication System
Todd Ekenstam, Charles Matheny, Peter L. Reiher, Gerald J. Popek |
Distributed Parallel Databases | 3 |
| 2001 | Replication Requirements in Mobile Environments
David Ratner, Peter L. Reiher, Gerald J. Popek, Geoffrey H. Kuenning |
Mob. Networks Appl. | 2 |
| 2000 | URL Forwarding and Compression in Adaptive Web CachingabstractWeb caching is generally acknowledged as an important service for alleviating focused overloads when certain WWW servers' contents suddenly become popular. Cooperative caching systems are more effective than independent caches due to the larger collective backing store that cooperation creates. One such system currently being developed at UCLA, adaptive Web caching (AWC), uses an application-level forwarding table to locate the nearest copy of a requested URL's contents. This paper describes one specific design in AWC, a simple URL table compression algorithm allowing efficient content information-sharing among neighboring caches. The compression algorithm is based on a hierarchical URL decomposition to aggregate URL sharing common prefixes and an incremental hashing function to minimize collisions between prefixes. The algorithm's collision rate is derived analytically and verified by five sets of Web trace data. The results demonstrate that the collision rate is bounded and has little impact on page fetching latency. Finally, this compression method is compared to the summary cache method. B. Scott Michel, Konstantinos Nikoloudakis, Peter L. Reiher, Lixia Zhang 0001 |
INFOCOM | 3 |
| 2000 | A conceptual framework for network and client adaptation
B. R. Badrinath, Armando Fox, Leonard Kleinrock, Gerald J. Popek, Peter L. Reiher, Mahadev Satyanarayanan |
Mob. Networks Appl. | 5 |
| 1999 | A simulation evaluation of optimistic replicated filing in mobile environmentsabstractOptimistic replication of data is becoming increasingly popular in mobile environments, but its performance and scaling characteristics are not well understood. This paper presents a simulation evaluation of optimistic replicated filing in a mobile environment. We first compare full and selective optimistic replication systems to capture the properties required for scaling. We then show that the presence of portable computers in optimistically replicated filing systems achieves a 60-percent cost reduction (e.g., computing resources) with only a 10-percent degradation of service quality (e.g., consistency of data perceived by users). This finding reveals certain similarities between the network disconnection interval and frequency of data synchronization. The research suggests new guidelines for design of optimistic replication systems. An-I Wang, Peter L. Reiher, Rajive L. Bagrodia |
IPCCC | 2 |
| 1999 | Securing information transmission by redundancyabstractMany approaches have been used or proposed for providing security Ior inlormation dissemination over networks, including encryption, authentication, and digital signafures.These mechanisms do not, however, necessarily help ensure that a message is delivered at all.Attacks that try to destroy or intercept security messal~es require other mechanisms.Authenticated acknowledgements are sometimes useful for this purpose, but do not scale well.This paper discusses the use of redundancy to combat attempts to prevent intbrmation dissemination.Redundancy has been widely used in other areas, such as high availability data storage, file replication, and some faulttolerant systems.The se_curity problem has different characteristics that require different approaches to redundancy.We present one example of using redundancy to increase assurance of security updates delivery. Jun Li 0001, Peter L. Reiher, Gerald J. Popek |
NSPW | 2 |
| 1998 | Perspectives on Optimistically Replicated, Peer-to-Peer FilingabstractThis research proposes and tests an approach to engineering distributed file systems that are aimed at wide-scale, Internet-based use. The premise is that replication is essential to deliver performance and availability, yet the traditional conservative replica consistency algorithms do not scale to this environment. Our Ficus replicated file system uses a single-copy availability, optimistic update policy with reconciliation algorithms that reliably detect concurrent updates and automatically restore the consistency of directory replicas. The system uses the peer-to-peer model in which all machines are architectural equals but still permits configuration in a client-server arrangement where appropriate. Ficus has been used for six years at several geographically scattered installations. This paper details and evaluates the use of optimistic replica consistency, automatic update conflict detection and repair, the peer-to-peer (as opposed to client-server) interaction model, and the stackable file system architecture in the design and construction of Ficus. The paper concludes with a number of lessons learned from the experience of designing, building, measuring, and living with an optimistically replicated file system. © 1998 John Wiley & Sons, Ltd. Thomas W. Page Jr., Richard G. Guy, John S. Heidemann, David Ratner, Peter L. Reiher, Ashish Goel, Geoffrey H. Kuenning, Gerald J. Popek |
Softw. Pract. Exp. | 5 |
| 1997 | Experience with an Automated Hoarding System
Geoffrey H. Kuenning, Peter L. Reiher, Gerald J. Popek |
Pers. Ubiquitous Comput. | 2 |
| 1989 | The Performance of a Distributed Combat Simulation with the Time Warp Operating SystemabstractAbstract This paper analyzes the performance of a discrete‐event combat simulation executed on a parallel processor under control of the Time Warp Operating System. Time Warp is in a class of distributed simulation methods called Optimistic methods which have proven to be useful over a wide range of simulations. The combat simulation used for this performance study, called STB88, is a division‐corps model incorporating a number of different types of computations. The speed‐up for three versions of this model on the Caltech/JPL Mark III Hypercube and the BBN Butterfly parallel processors was measured relative to an efficient sequential execution of the same model on the same hardware. The results indicate that STB88 version 1 achieves a speed‐up of 28.6 on 60 Mark III processors, while STB88 version 2 achieves a speed‐up of 36.8 on 100 Butterfly processors. Version 3 of STB88 achieved a speed‐up of 38.5 on 128 Mark III processors. The versions differed only in their interface to Time Warp. On the Butterfly, the sequential execution completed in 2 hours, while the 100 processor execution completed in 3.2 minutes. Frederick Wieland, L. Hayley, A. Feinberg, Mike Di Loreto, Leo Blume, J. Ruffles, Peter L. Reiher, Brian Beckman, Phil Hontalas, Steve Bellenot, David R. Jefferson |
Concurr. Pract. Exp. | 7 |